perhaps we need an RFC that defines this type of approach (pages "secured" behind easily guessable urls) as public information.
There could also be other RFCs covering our usage of the internet, and our expectations of what our rights are as internet users. Or perhaps stick that all in one "definitive" RFC.